SYN Cookies in Firewalls and Load Balancers

A commonly used distributed denial of service (DDoS) attack is known as SYN-flooding. In this type of attack, the attacker sends a series of TCP SYN packets that typically originate from spoofed IP addresses. The constant flood of SYN packets can prevent servers within the data center from handling legitimate connection requests. You can use firewalls and security appliances such as the Cisco ASA and the Cisco PIX enabled with the SYN cookies algorithm to combat SYN flood attacks. In large data centers, the Cisco Firewall Services Module (FWSM), for the Catalyst 6500 series switches, is typically used for this same purpose. Figure 10-1 demonstrates how TCP synchronization message (SYN) cookies work in the Cisco Adaptive Security Appliance (ASA), the Cisco PIX, and the FWSM for the Cisco Catalyst 6500 switches. In this example, a Cisco FWSM is used.

Figure 10-1 SYN Cookies in FWSM

Figure 10-1 SYN Cookies in FWSM

Client FWSM Server

Client FWSM Server

The following steps are illustrated in Figure 10-1:

1 A client machine attempts a TCP connection to a web server behind the FWSM and sends the initial SYN packet to the firewall.

2 When the embryonic (half-open) connection limit is reached, the Cisco ASA, Cisco PIX, or Cisco FWSM can act as a proxy for the server and generate a SYN-ACK response to the client SYN request. The SYN-ACK reply has a "cookie" in the sequence (SEQ) field of the TCP header. The cookie is a message digest 5 algorithm (MD5) authentication of the source and destination IP addresses and port numbers. All the connection requests are rebuilt from these cookies.

3 The acknowledgement (ACK) packet SEQ field has the value of the cookie+1. In this case, when the FWSM receives an ACK from the client, it "authenticates" the client and allows the connection to the server.

4 The FWSM sends its own SYN packet to the server.

5 The server replies with an ACK.

6 The FWSM sends its SYN-ACK to the server, and the connection is built.

On the Cisco FWSM, you can use the show np command to view SYN cookie statistics.

Example 10-1 shows the output of the show np 2 syn command on an FWSM.

Example 10-1 Output of show np 2 syn Command

FWSM# show np 2 syn

Fast Path Syn Cookie Statistics Counters (NP-2)

SYN_COOKIE: Syn cookie secret wheel index : 16

SYN_COOKIE: Total number of SYNs intercepted : 231356987

SYN_COOKIE: Total number of ACKs intercepted : 204

SYN_COOKIE: Total number of ACKs dropped after lookup : 0

Example 10-1 Output of show np 2 syn Command (Continued)

SYN

COOKIE

Total number of ACKs successfully validated

193

SYN

COOKIE

Total number of ACKs Dropped: Secret Expired

11

SYN

COOKIE

Total number of ACKs Dropped: Invalid Sequence :

0

SYN

COOKIE

Total number of Syn Cookie Entries inserted by NP3

12

SYN

COOKIE:

ACKs dropped: Syn cookie ses not yet established :

0

SYN

COOKIE:

Leaf allocation failed :

0

SYN

COOKIE:

Leaf insertion failed :

2088

In the highlighted line in Example 10-1, you can see that the total number of intercepted SYN packets is 231356987. This is most definitely indicative of a SYN flood.

Load-balancing solutions such as the Cisco Content Switching Module (CSM) also support SYN cookies. You can deploy the CSM in inline mode or one-arm mode. Figure 10-2 illustrates a CSM configured in inline mode. Traffic from certain applications cannot be load-balanced because of the nature of those applications. In Figure 10-2, the traffic that cannot be load-balanced is labeled as direct traffic.

Figure 10-2 CSM in Inline Mode

Figure 10-2 CSM in Inline Mode

In Figure 10-2, the CSM is configured with both physical interfaces that are connected to the network with all traffic passing through the CSM. Figure 10-3 illustrates the one-arm CSM design.

The CSM uses a virtual IP address. In a "one-arm" design, you can combine it with a Cisco FWSM. One of the major benefits of using a CSM one-arm design in combination with the Cisco FWSM is that the CSM protects against DoS attacks directed at its virtual IP address, and the Cisco FWSM protects against attacks directed at non-load-balanced servers.

The use of SYN cookies has certain limitations. For example, SYN cookies cannot carry TCP options that are set up in SYN packets; SYN cookies can carry only an encoding of the maximum segment size (MSS) value of the server. Some TCP options are used for performance and scalability (for example, large windows, selective acknowledgement, and so on). Another limitation of SYN cookies is that they do not protect against established connection attacks.

Figure 10-3 CSM in One-Arm Mode

Figure 10-3 CSM in One-Arm Mode

Syn Cookies

NOTE Established connection attacks are attacks that exploit vulnerabilities after a connection has been established such as a buffer overflow to a specific application.

Continue reading here: Cisco Net Flow in the Data Center

Was this article helpful?

0 0